DOCUMENTATION10 min

Article 50: Transparency Duties and Labelling AI-Generated Content

A practical guide to the EU AI Act's Article 50 transparency obligations: the AI-interaction disclosure, machine-readable marking of synthetic content, emotion-recognition and biometric-categorisation notices, and deepfake and public-interest-text disclosure — including the editorial and artistic carve-outs and how this interacts with GPAI marking.

V
Veritome Team
12.07.2026

Key Takeaways

  • 1Article 50 sits outside the risk tiers — it is a 'specific transparency' layer that can apply even to systems that are otherwise low-risk, and it applies from 2 August 2026.
  • 2Article 50(1): providers must design AI systems that interact directly with people — chatbots, voice assistants — so users are told they are dealing with an AI, unless it is obvious.
  • 3Article 50(2): providers of generative AI must mark synthetic audio, image, video and text outputs as artificially generated in a machine-readable, detectable format.
  • 4Article 50(3): deployers of emotion-recognition or biometric-categorisation systems must inform the people exposed to them.
  • 5Article 50(4): deployers must disclose deepfakes, and must disclose AI-generated text published to inform the public on matters of public interest — subject to an editorial-responsibility carve-out for text and an artistic/creative exception.
  • 6For an SME the practical work is three things: a chatbot disclosure line, a synthetic-media watermark and label, and a short labelling policy that says which systems are in scope and who owns the disclosures.

Where Article 50 sits in the Act

Most of the EU AI Act is organised around risk: prohibited, high-risk, limited, minimal. Article 50 cuts across that structure. It imposes 'specific transparency obligations' that attach to particular kinds of AI regardless of their risk tier — a perfectly low-risk chatbot or image generator can be squarely in scope. The unifying idea is honesty about provenance: people should know when they are dealing with a machine, and when content they are looking at was made or altered by one.

The obligations apply from 2 August 2026. They used to share that date with the bulk of the high-risk regime; Regulation (EU) 2026/1744 deferred high-risk to 2 December 2027 and left Article 50 exactly where it was, which is why transparency is now the live obligation and high-risk is the one with runway. Article 50 is written in four operative paragraphs, and it splits its duties between providers (who build the disclosure into the system) and deployers (who switch it on and disclose in context). Getting the provider/deployer split right is half the work.

  • Article 50(1) — AI-interaction disclosure (provider duty).
  • Article 50(2) — machine-readable marking of synthetic content (provider duty).
  • Article 50(3) — emotion-recognition / biometric-categorisation notice (deployer duty).
  • Article 50(4) — deepfake and public-interest-text disclosure (deployer duty).

Article 50(1): tell people they are talking to an AI

Providers must ensure that AI systems intended to interact directly with natural persons are designed and developed so that the people concerned are informed that they are interacting with an AI system. This is the chatbot and voice-assistant rule. The disclosure is not required where it is obvious from the point of view of a reasonably well-informed, observant and circumspect person, taking account of the circumstances and context — and there is a narrow exception for systems authorised by law to detect, prevent or investigate criminal offences.

In practice the 'obvious' get-out is thinner than teams hope. A support widget on your website that answers in fluent prose is not obviously a bot to an ordinary user, so the safe reading is to disclose. The information must be given at the latest at the point of first interaction, clearly and distinguishably.

Article 50(2): mark synthetic content as artificially generated

Providers of AI systems — including general-purpose AI systems — that generate synthetic audio, image, video or text must ensure the outputs are marked in a machine-readable format and detectable as artificially generated or manipulated. The technical solutions must be effective, interoperable, robust and reliable as far as is technically feasible, taking account of the specificities and limitations of different content types. This is the watermarking and provenance-metadata obligation, and it is a provider duty on the generative system.

There are sensible limits. The duty does not bite where the AI performs a purely assistive function for standard editing, or where it does not substantially alter the input data supplied by the deployer — a grammar corrector is not producing a 'deepfake'. As with 50(1), there is a law-enforcement carve-out.

Article 50(3): notice for emotion recognition and biometric categorisation

Deployers of an emotion-recognition system or a biometric-categorisation system must inform the natural persons exposed to it of the operation of the system, and must process any personal data in line with the GDPR and related law. This is a deployer duty, in context, at the point of exposure. Where such use is permitted by law for criminal-offence purposes, the specific safeguards of that regime apply instead.

The practical trigger is exposure, not consent: if your premises or product run emotion recognition or sort people into biometric categories, the people affected have to be told it is happening.

Article 50(4): deepfakes and public-interest text

Article 50(4) carries two distinct deployer duties, and both come with carve-outs that matter.

Deepfakes

Deployers of an AI system that generates or manipulates image, audio or video content constituting a deep fake must disclose that the content has been artificially generated or manipulated. The important exception is the artistic one: where the content is part of an evidently artistic, creative, satirical, fictional or analogous work or programme, the obligation is limited to disclosing the existence of the generation in an appropriate manner that does not hamper the display or enjoyment of the work. A caption in the credits, not a watermark across the frame.

AI-generated text on matters of public interest

Deployers of an AI system that generates or manipulates text which is published with the purpose of informing the public on matters of public interest must disclose that the text has been artificially generated or manipulated. Here the carve-out is editorial: the duty does not apply where the AI-generated content has undergone a process of human review or editorial control and a natural or legal person holds editorial responsibility for the publication. In other words, a newsroom that runs an AI draft past a human editor who owns the piece is outside this specific duty — an automated feed that publishes unreviewed AI copy is not.

  • Deepfake disclosure has an artistic/creative/satirical exception — disclose, but without hampering the work.
  • Public-interest AI text has an editorial-responsibility carve-out — human review plus a named editor holding responsibility takes it out of scope.
  • Neither carve-out touches the machine-readable marking duty on the generative provider under Article 50(2).

How this interacts with GPAI marking

There is a natural overlap between Article 50(2) and the general-purpose AI regime. The model that actually produces the synthetic output is usually a GPAI model, and the machine-readable marking has to be built into the generation itself. If you are a downstream SME shipping a product on top of a foundation model, the model provider's watermarking and provenance tooling is what makes your outputs detectable — but the Article 50(2) obligation to mark still sits on you as the provider of the generative system.

The practical consequence: when you choose a generative model or API, ask what marking it supports (C2PA-style content credentials, provenance metadata, watermarking) and treat that as a compliance input, not just a feature. You are relying on the upstream marking to satisfy a duty the Act places on your own system.

Practical labelling steps for an SME

You do not need a large programme to meet Article 50 — you need three concrete things, documented so you can show them:

  • Chatbot disclosure — add a clear, first-contact notice to any AI that talks to users ('You're chatting with an AI assistant'), placed so a reasonable person could not miss it. Cover voice as well as text.
  • Synthetic-media marking and labels — for anything your product generates, enable the provider's machine-readable marking (watermark / content credentials) and add a visible 'AI-generated' label where a person will see the output. Keep the deepfake and public-interest-text carve-outs in mind for editorial contexts.
  • A labelling policy — a short internal document that lists which of your systems interact with people or generate content, states how each disclosure or mark is applied, names the owner of the disclosure copy, and sets a review date. This is the artefact a regulator or customer will actually ask to see.

The point of writing it down is that transparency duties are easy to satisfy on day one and easy to let drift — a redesign quietly drops the chatbot banner, or a new feature starts generating images without a label. A living policy that is reviewed is what keeps you compliant, rather than compliant-once.

Where Veritome fits

Veritome's engine surfaces the Article 50 obligations automatically from how a system is described: flag a system as a chatbot and it raises the 50(1) interaction-disclosure duty; flag it as generating content and it raises the 50(2) marking duty; flag deepfake or emotion-recognition use and it raises the 50(3) and 50(4) duties, with the editorial and artistic carve-outs noted where they apply. Each obligation becomes a tracked item with an owner, evidence and a review date, so the disclosures stay in place through redesigns rather than being a launch-day checkbox.

This article is general information about the EU AI Act and how Article 50 works — it is not legal advice. For how these transparency duties apply to a specific product, especially the editorial and artistic carve-outs, take qualified advice.

Frequently Asked Questions

When do the Article 50 transparency obligations apply?

From 2 August 2026. Regulation (EU) 2026/1744 deferred the high-risk regime to 2 December 2027 but did not move Article 50, so it applies now. Article 50 sits outside the risk tiers, so a system can be low-risk overall and still owe these specific transparency duties.

Do I have to tell users they are talking to a chatbot?

Yes. Under Article 50(1), a provider must design an AI system that interacts directly with people so those people are informed they are dealing with an AI system, at the latest at first interaction. The only relief is where it is obvious to a reasonably well-informed person given the context — which is a thinner exception than it sounds for a fluent support bot — plus a narrow law-enforcement carve-out.

What does 'mark AI-generated content in a machine-readable format' mean?

Article 50(2) requires providers of generative AI to ensure synthetic audio, image, video and text outputs are marked so they are detectable as artificially generated or manipulated, using solutions that are effective, interoperable, robust and reliable as far as technically feasible. In practice this means watermarking and provenance metadata (for example C2PA-style content credentials), usually built into the generating model. It does not apply to purely assistive editing that does not substantially alter the input.

Do I have to label deepfakes and AI-written articles?

Deployers must disclose deepfakes — AI-generated or manipulated image, audio or video — under Article 50(4), except that for evidently artistic, creative, satirical or fictional works the disclosure need only be made in a way that does not hamper the work. Deployers must also disclose AI-generated text published to inform the public on matters of public interest, unless the text underwent human review or editorial control and a person holds editorial responsibility for it.

How does Article 50 relate to the GPAI rules?

The machine-readable marking under Article 50(2) is usually produced by the underlying general-purpose AI model, so a downstream provider relies on the model provider's watermarking and provenance tooling. But the Article 50(2) obligation to mark outputs still rests on the provider of the generative system, so when choosing a model or API you should treat its marking support as a compliance requirement, not just a feature.

What should an SME actually do to comply with Article 50?

Three things: add a clear first-contact disclosure to any AI that interacts with people (text and voice); enable machine-readable marking plus a visible 'AI-generated' label on any content your product generates; and keep a short labelling policy that lists the systems in scope, how each disclosure is applied, who owns it, and when it is reviewed. Documenting and reviewing it is what keeps you compliant as products change.

EU AI Act updates, in your inbox

Deadlines, enforcement news and practical compliance guidance. One confirmation email first, then only the updates — one-click unsubscribe in every one.